Case study
May 2026 — ShinyHunters / Instructure Canvas breach
- Incident
- Third-party SaaS breach of Instructure's Canvas LMS, with downstream impact at U.S. higher-education institutions including Rutgers.
- Date
- May 2026
- Threat actor
- ShinyHunters
A textbook third-party SaaS breach that bypasses institutional perimeter controls — the vendor's credentials were the attack surface. AegisGrid's upstream and downstream workflows share the same architecture: local inference, signed audit log, human in command.
Sources: Rutgers IT alert (it.rutgers.edu/alerts/2026/05/04/nationwide-security-breach-involving-canvas/); Daily Targum coverage; NJ 101.5 coverage.